back to article North Koreans clone open source projects to plant backdoors, steal credentials

North Korea's Lazarus Group compromised hundreds of victims across the globe in a massive secret-stealing supply chain attack that was ongoing as of earlier this month, according to security researchers. The crew's latest operation, dubbed Phantom Circuit, planted backdoors in clones of legitimate software packages and open …

  1. mahan
    Alert

    This yet again underlines why servers should NOT have direct internet access.

    They should only have whitelisted connections to distribution repositories and update servers to stay current with security patches. Letting servers freely chat with the internet is asking for trouble.

    In this case, proper egress filtering would have prevented both the C2 connections and the Dropbox exfiltration.

  2. Irongut Silver badge

    Legitimate software?

    All the packages listed are web 3 crypto scam nonsense, nothing legitimate about that software.

    Any low life dev getting infected deserves what they get.

    Signed,

    A dev with morals

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like